Key data
| Regulation | Commission Implementing Regulation (EU) 2026/1755, of 20 July 2026 |
|---|---|
| Publication | 21 July 2026 |
| Entry into force | 20 July 2026 |
| Affected parties | Providers and operators of artificial intelligence systems in the EU, especially high-risk or prohibited AI |
| Category | European Regulation |
| Reference standard | Regulation (EU) 2024/1689 — AI Act |
| Year | 2026 |
If your company develops, deploys or operates artificial intelligence systems in the European Union, the European Commission can now formally investigate you. Commission Implementing Regulation (EU) 2026/1755, published on 21 July 2026 and in force since 20 July, completes the enforcement mechanism of the Regulation (EU) 2024/1689 (AI Act). Until now the substantive rule existed; now the concrete procedure for applying it also exists.
This is not a minor change. It means the Commission now has the procedural tools necessary to open cases, impose precautionary measures and impose sanctions. Companies that have not prepared their defense are in a position of real risk.
What does this regulation establish?
Implementing Regulation 2026/1755 develops the internal procedures that the European Commission will follow when processing investigations into possible AI Act violations. The aspects it specifies are as follows:
| Procedural aspect | What it regulates |
|---|---|
| Deadlines | Maximum and minimum timeframes for each phase of the investigation procedure |
| Hearing rights | Mechanisms that guarantee the investigated company the right to be heard before any decision |
| Access to the file | Conditions under which the company can consult the documentation gathered by the Commission |
| Precautionary measures | Possibility of imposing provisional restrictions while the investigation is being processed |
| Notifications to interested parties | Form and channel through which the Commission formally communicates the initiation and development of the procedure |
| Contradiction mechanisms | Procedural guarantees that allow the company to rebut the charges with evidence and arguments |
In practical terms, this regulation is the "procedure manual" that the Commission will follow whenever it suspects that an AI provider or operator is violating the AI Act. Without this framework, direct Commission enforcement was not operational. With it, it is.
Economic and operational impact
The impact is not measured in a rate or fixed amount: it is measured in the risk of being exposed to a sanctioning procedure without being prepared. The AI Act establishes penalties of up to 35 million euros or 7% of worldwide turnover for the most serious violations (prohibited AI systems). For violations related to high-risk systems, fines can reach 15 million euros or 3% of global turnover.
Regulation 2026/1755 does not create new sanctions, but activates the mechanism to apply them. The specific operational consequences are:
- Immediate precautionary measures: the Commission can restrict or suspend the use of an AI system while it investigates, even before issuing a final decision.
- Access to the file with limits: the company has the right to consult the file, but under conditions that must be known in advance to exercise it effectively.
- Adjusted deadlines: the procedure timeframes are fixed, which means the company must be able to respond quickly and with prepared documentation.
- Cost of defense: facing a procedure of this type without prior preparation implies significant legal and internal management costs.
For technology SMEs, the risk is especially high: they lack the internal legal teams that large corporations have to respond within the set deadlines.
Who does it affect?
- Providers of high-risk AI systems (according to Annex III of the AI Act): companies that develop or market AI used in recruitment, credit, education, critical infrastructure, justice, migration or security.
- Operators of high-risk AI systems: companies that deploy or use these systems in their processes, even if they did not develop them.
- Companies with prohibited AI systems: any organization that operates systems classified as unacceptable under the AI Act (subliminal manipulation, social scoring, real-time biometric recognition in public spaces with limited exceptions).
- Technology SMEs with AI-based products or services aimed at the European market, regardless of where they are established.
- Large corporations from any sector that have integrated high-risk AI into their operations (banking, insurance, health, human resources, logistics).
- Legal and compliance advisors who advise technology sector companies on AI Act compliance.
Practical example
A Spanish human resources software company markets an AI system that automatically filters candidates in selection processes. This system is classified as high-risk under Annex III of the AI Act.
The European Commission receives a complaint about possible discriminatory biases in the algorithm. With Regulation 2026/1755 in force, the procedure would develop as follows:
- The Commission formally notifies the company of the start of the investigation, following the channels and procedures established in the regulation.
- The company receives access to the file under the conditions set and has the regulatory deadlines to prepare its response.
- The hearing mechanism is activated: the company can present evidence and arguments before any decision.
- If the Commission sees immediate risk, it can impose precautionary measures that suspend the commercialization of the system while the case is resolved.
- Without prepared compliance documentation (conformity assessment, registration in the EU database, risk management system), the company cannot effectively exercise its defense within the set deadlines.
This scenario, previously theoretical, is now completely operational.
What should companies do now?
- Classify all AI systems in use or in development according to the AI Act categories (prohibited, high-risk, limited risk, minimal). This classification determines whether you are within the scope of direct Commission enforcement.
- Review the risk management system for high-risk systems: technical documentation, conformity assessment, registration in the EU database. Without this, there is no possible defense against a case.
- Designate an internal AI Act compliance officer with the ability to respond within the deadlines set by the new procedural regulation.
- Prepare a protocol for responding to Commission notifications: who acts, within what timeframe, what documentation is gathered and what legal advice is activated.
- Review contracts with AI providers to ensure that compliance obligations are clearly assigned between provider and operator.
- Train the management team on the hearing rights and access to the file recognized by Regulation 2026/1755, to be able to exercise them effectively if an investigation comes.
Frequently asked questions
When can the European Commission investigate my company for the AI Act?
As of 20 July 2026, the date Implementing Regulation 2026/1755 enters into force, the Commission has the complete procedural framework to open formal investigations. It can act on its own initiative or following complaints. Companies that are providers or operators of high-risk or prohibited AI systems are the main targets of this direct enforcement.
What are the precautionary measures of the AI Act and how do they affect me?
Regulation 2026/1755 regulates the possibility of the Commission imposing precautionary measures while processing an investigation. This means that, before issuing a final decision, it can restrict or suspend the commercialization or use of an AI system if it sees immediate risk. For a company, this can mean the paralysis of a product or service without a final sanction yet.
Do I have the right to consult the file if the Commission investigates me?
Yes. Implementing Regulation 2026/1755 expressly establishes the right of access to the file for investigated companies, although under specific conditions. It also recognizes the right to be heard, which allows presenting evidence and arguments before any decision. Knowing these conditions in advance is key to being able to exercise defense effectively within the set deadlines.
Does this regulation affect SMEs or only large technology companies?
It affects all companies that are providers or operators of high-risk or prohibited AI systems in the EU, regardless of their size. The regulatory summary itself expressly states that both technology SMEs and large corporations in the sector must review their compliance systems. SMEs are especially vulnerable because they usually lack internal legal teams prepared to respond within the procedure deadlines.
What is the difference between the AI Act (2024/1689) and this Implementing Regulation 2026/1755?
The AI Act (Regulation 2024/1689) is the substantive rule: it establishes which AI systems are prohibited, which are high-risk and what obligations they must comply with. Implementing Regulation 2026/1755 is the procedural regulation: it specifies how the Commission will investigate and sanction when it suspects a violation. Without this second regulation, direct Commission enforcement was not operational. With it, it has been since 20 July 2026.
Official source
Consult full regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601755